Vulnerabilities > Zohocorp > Manageengine Servicedesk Plus > 11.1

DATE CVE VULNERABILITY TITLE RISK
2020-06-12 CVE-2020-14048 Missing Authentication for Critical Function vulnerability in Zohocorp Manageengine Servicedesk Plus
Zoho ManageEngine ServiceDesk Plus before 11.1 build 11115 allows remote unauthenticated attackers to change the installation status of deployed agents.
network
low complexity
zohocorp CWE-306
7.5
2020-05-18 CVE-2020-13154 Missing Authorization vulnerability in Zohocorp Manageengine Servicedesk Plus 11.1
Zoho ManageEngine Service Plus before 11.1 build 11112 allows low-privilege authenticated users to discover the File Protection password via a getFileProtectionSettings call to AjaxServlet.
network
low complexity
zohocorp CWE-862
6.5
2019-08-21 CVE-2019-15045 Information Exposure vulnerability in Zohocorp Manageengine Servicedesk Plus
AjaxDomainServlet in Zoho ManageEngine ServiceDesk Plus 10 allows User Enumeration.
network
low complexity
zohocorp CWE-200
5.3
2019-08-14 CVE-2019-15046 Improper Authentication vulnerability in Zohocorp Manageengine Servicedesk Plus
Zoho ManageEngine ServiceDesk Plus 10 before 10509 allows unauthenticated sensitive information leakage during Fail Over Service (FOS) replication, aka SD-79989.
network
low complexity
zohocorp CWE-287
7.5
2018-03-30 CVE-2018-5799 Cross-site Scripting vulnerability in Zohocorp Manageengine Servicedesk Plus
In Zoho ManageEngine ServiceDesk Plus before 9403, an XSS issue allows an attacker to run arbitrary JavaScript via a /api/request/?OPERATION_NAME= URI, aka SD-69139.
network
low complexity
zohocorp CWE-79
6.1